Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly us
A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changi
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbi
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be f
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, c
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may le
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which m
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index i
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input index is not validated, which may lea
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data si
NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to
A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore
There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an a
A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal informat
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authenticatio
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential pr
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirec
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege e
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race proble
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permission
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final.
A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissi
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer ov
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by I
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values ou
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by Ima
A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by Ima
A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers,
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local atta
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This fil
A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to g
This release fixes a Cross Site Request Forgery vulnerability was found in Red Hat CloudForms which forces end users to
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started